Comment by jaredklewis

Comment by jaredklewis 2 hours ago

0 replies

I’m confused.

Bounties for security holes make sense because you don’t need to submit the patch, just find the hole.

And bounties for open source (like in this case) also make sense because you have everything you need to submit a patch.

But for everything else (like big tech, startups, and so on) bounties can’t fix bugs because even if I find a bug, how am I going to patch it without access to the source code? How can someone submit a patch to Netflix or whatever?

IME your average SV startup has a long list of bugs they are aware of, but just haven’t gotten around to fixing because other priorities are in the way. But people can’t help patch unless you have an open development process.

Am I missing something?